default IdP metadata for Shib IdP V3

Tom Scavo trscavo at gmail.com
Wed Jan 20 08:10:34 EST 2016


On Tue, Jan 19, 2016 at 5:58 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 1/19/16, 5:38 PM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
>
>>I know what the encryption certificate is for (IdP V3 supports inbound
>>encryption) but why are there two signing certificates?
>
> Separate TLS and signing keys.

I understand why the back-channel TLS and signing keys are different
(because they represent completely different security models such that
the compromise of one key does not necessarily imply compromise of the
other) but I still don't understand why the signing certificate and
the encryption certificate aren't the same. Can you explain?

Thanks,

Tom


More information about the users mailing list